57,566 vulnerabilities published in 2026
Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Quality Workbench HTML system). Supp
Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Import And Export). Supp
Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Install). Suppor
Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Self Service Benefits). Su
Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration
A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of t
When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be v
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all
Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.
Contributor Broken Access Control in Style Kits <= 2.6.5 versions.
A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file do
Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that
A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/mod
A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file s
A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/
A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function
Tanium addressed a SQL injection vulnerability in Patch.
GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifyi
MathLive provides web components for math display and input. Prior to 0.110.0, MathLive fails to escape text-mode conten
Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to b
An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across ident
IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2,
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the se
FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to
Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_node fields in inven
A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function set_sys_adm of the file ad
A vulnerability was identified in jeequan jeepay up to 3.2.9. This vulnerability affects the function WebSecurityConfig
A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of
A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the file sar2html.py of the compo
A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurv
A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The affected element is an unknown function of the file
A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affect
A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_
A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file ag
A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browse
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolv
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the termi
A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView o
A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown fun
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,
A vulnerability was determined in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d4
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote atta
A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions
A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classify_command_risk of the fi
A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of
A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functiona
A vulnerability has been found in cosmicstack-labs mercury-agent up to 1.1.12. This vulnerability affects the function P
A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the function Agent.handleBg
A vulnerability was determined in cosmicstack-labs mercury-agent up to 1.1.12. Impacted is the function SubAgent.run of
A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. Affected is the function handleCreateAgent of the file s
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started